PRIVACY POLICY

acouncilbility Platform
Effective Date: 25/08/2025
Last Updated: 25/08/2025

Privacy-By-Design Summary

acouncilbility is built with military-grade privacy and security. We use anonymous seed phrase accounts, collect minimal data only when you submit reports, and never track your location or activities in the background. Private reports are protected with AES256 + RSA2048 encryption - even we cannot read them, only the intended government authority can decrypt your private reports.

1. INTRODUCTION

This Privacy Policy explains how acouncilbility ("we," "us," or "our") collects, uses, discloses, and protects your personal information when you use our mobile application and services (collectively, "Services").

acouncilbility is a civic reporting platform that allows users to submit reports about infrastructure, services, and community issues to government authorities and responsible organizations.

We are committed to protecting your privacy while providing transparent civic accountability tools. This Policy is designed to comply with:

2. INFORMATION WE COLLECT

2.1 Information Collection Overview

We collect minimal information necessary to provide our civic reporting services. We do not collect personal information in traditional ways and do not maintain profiles with names, email addresses, or phone numbers.

No Background Tracking: We do not continuously track, monitor, or collect your location, browsing behavior, or personal data outside of active report submissions.

2.2 Data We Collect When You Submit Reports

Data Type Collection Method Purpose
Location Coordinates Manual selection, GPS capture during submission, or EXIF data from photos Essential for report routing and public accountability mapping
Report Content Text descriptions you write Communicating the issue to responsible authorities
Photographs Images you choose to include Visual documentation for authorities and public accountability
Account Hash Generated from your 12-word seed phrase Anonymous account identification and report attribution
Device Metadata Technical information during submission Report processing and technical support
Timestamps Automatically captured during submission Report tracking and authority processing

2.3 Data We Do NOT Collect

3. ANONYMOUS ACCOUNT SYSTEM

3.1 Cryptographic Seed Phrase Technology

Our privacy-by-design approach uses a cryptographically secure anonymous account system:

3.2 Account Privacy Benefits

Cryptographic Security Notice: Your 12-word seed phrase and private keys are never transmitted to or stored on our servers. This ensures maximum privacy and security - but also means we cannot recover lost seed phrases or access locked accounts.

4. HOW WE USE YOUR INFORMATION

4.1 Primary Use Purposes

4.2 Public vs Private Reports

Public Reports:

Private Reports (Zero-Knowledge Encrypted):

5. INFORMATION SHARING AND DISCLOSURE

5.1 Government and Authority Sharing

We share report information with responsible authorities including:

5.2 Legal Basis for Sharing

Information sharing occurs under the following legal bases:

5.3 Public Disclosure for Public Reports

Important: Public reports and their location data become part of a permanent public record accessible to:

5.4 Third-Party Service Providers

We may share technical data with:

All service providers are contractually required to maintain data security and use limitations.

6. LOCATION DATA AND MAPPING

6.1 Location Collection

Location information is collected ONLY when you actively submit a report through:

No Passive Tracking: We never collect location data when you're not actively creating a report. The app does not run background location services or track your movements.

6.2 Location Data Usage

6.3 Location Privacy Limitations

Critical Notice: Location data included in public reports cannot be kept private and cannot be deleted after submission. This is fundamental to our civic accountability mission.

7. DATA RETENTION

7.1 Report Data Retention

7.2 Legal and Public Interest Basis

Long-term retention is justified by:

7.3 Account Deactivation

When you deactivate your account:

8. YOUR PRIVACY RIGHTS

8.1 Australian Privacy Rights

Under the Privacy Act 1988 (Cth), you may have rights to:

8.2 Limitations on Privacy Rights

Important Limitations: Due to the civic accountability nature of our service:

8.3 GDPR Rights (EU Users)

If you are located in the European Union, you may have additional rights under GDPR, including:

These rights are subject to limitations for public interest activities and legal compliance requirements.

9. DATA SECURITY

9.1 Military-Grade Encryption

We implement military-grade security measures that exceed industry standards:

Private Report Zero-Knowledge Encryption

Hybrid AES256 + RSA2048 Encryption: Private reports are encrypted using military-grade hybrid encryption combining AES256 (for data) and RSA2048 (for key exchange).

Zero-Knowledge Architecture: Even acouncilbility staff cannot read private report content - only the intended government authority can decrypt reports using their private key.

9.2 Advanced Cryptographic Architecture

9.3 Transport Layer Security

9.4 Infrastructure Security

9.5 Additional Security Measures

9.6 Data Breach Response

In the event of a data breach, we will:

10. CHILDREN'S PRIVACY

10.1 Age Restriction

Our Services are intended for users aged 18 and above only. We do not knowingly collect personal information from children under 18.

10.2 Child Privacy Protection

If we discover that a child under 18 has provided personal information:

11. INTERNATIONAL DATA TRANSFERS

11.1 Cross-Border Transfers

Your data may be transferred to and stored in countries other than your country of residence, including:

11.2 Transfer Protections

International transfers are protected through:

12. THIRD-PARTY INTEGRATIONS

12.1 Government Authority Systems

We integrate with various government systems for report submission. These authorities have their own privacy policies and data handling practices that we cannot control.

12.2 Mapping and Location Services

Our app may use third-party mapping services for location selection and display. These services operate under their own privacy policies.

12.3 Analytics and Performance

We may use privacy-compliant analytics services to monitor:

13. COOKIES AND TRACKING

13.1 Mobile App Data Storage

Our mobile app may store technical data locally on your device including:

13.2 Website Cookies (if applicable)

Our website may use minimal cookies for:

We do not use advertising cookies or tracking cookies for marketing purposes.

14. LEGAL COMPLIANCE AND LAW ENFORCEMENT

14.1 Legal Disclosure

We may disclose information when required by law, including:

14.2 Government Access

Government authorities may access report data through:

15. YOUR CHOICES AND CONTROLS

15.1 Report Privacy Selection

For each report, you can choose:

Note: This choice cannot be changed after submission.

15.2 Location Data Control

You control location inclusion by:

15.3 Account Management

16. DATA PROTECTION COMPLIANCE

16.1 Australian Privacy Principles Compliance

We exceed Australian Privacy Principles requirements through advanced technical measures:

16.2 Enhanced Security Compliance

Our security architecture exceeds regulatory requirements:

16.2 Lawful Basis Documentation

We maintain documentation of lawful bases for processing including:

17. APP STORE SPECIFIC DISCLOSURES

17.1 Google Play Store Compliance

This app exceeds Google Play privacy and security requirements:

17.2 Apple App Store Compliance

This app exceeds Apple App Store privacy and security requirements:

17.3 Enhanced Security Features for App Stores

18. CONTACT AND COMPLAINTS

18.1 Privacy Officer Contact

For privacy-related questions, complaints, or requests:

Email: privacy@acouncilbility.org
Website: https://acouncilbility.org/privacy
Response Time: We aim to respond to privacy inquiries within 30 days

18.2 Privacy Complaint Process

  1. Internal Complaint: Contact our privacy officer first
  2. Investigation: We will investigate your complaint within 30 days
  3. Response: We will provide a written response with our decision
  4. External Review: If unsatisfied, you may complain to the Office of the Australian Information Commissioner

18.3 Regulatory Contact Information

Office of the Australian Information Commissioner:
Website: https://www.oaic.gov.au
Phone: 1300 363 992
Email: enquiries@oaic.gov.au

19. UPDATES TO THIS PRIVACY POLICY

19.1 Policy Changes

We may update this Privacy Policy to reflect:

19.2 Notification of Changes

20. ADDITIONAL INFORMATION

20.1 Privacy by Design

Our platform is built with privacy-by-design principles:

20.2 Civic Transparency Balance

We balance privacy protection with civic accountability by:

Questions? If you have any questions about this Privacy Policy or our data practices, please contact our privacy officer at privacy@acouncilbility.org